Endpoint Operating System Security Flashcards
6 cards from real CCST practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Endpoint Operating System Security flashcards as text
What is the role of patch management in endpoint security?
Answer: To systematically apply security updates to fix known vulnerabilities
Patch management regularly applies security updates to fix vulnerabilities that attackers could exploit.
Which technology uses hardware to securely store cryptographic keys and verify system integrity at boot?
Answer: TPM (Trusted Platform Module)
TPM stores cryptographic keys and measures the boot process to verify system integrity before the OS loads.
What security risk do local administrator accounts pose on endpoints?
Answer: They allow unrestricted access that malware can exploit for full system compromise
Local admin accounts have full system access; if compromised, an attacker gains complete control.
What is Secure Boot and what does it protect against?
Answer: A UEFI feature that verifies digital signatures of boot software to prevent unauthorized code
Secure Boot checks digital signatures of bootloader, kernel, and drivers during startup, preventing bootkits and rootkits.
Why should USB port access be controlled on enterprise endpoints?
Answer: Uncontrolled USB access allows data exfiltration, malware introduction, and unauthorized devices
Uncontrolled USB ports enable data theft, malware infection, and rogue device attacks.
What is the function of a host-based intrusion detection system (HIDS)?
Answer: To monitor system activities and file changes to detect intrusion or policy violations
HIDS monitors file integrity, registry changes, log entries, and process activity to detect unauthorized modifications.